CVE-2025-25361
06.03.2025, 19:15
An arbitrary file upload vulnerability in the component /cms/CmsWebFileAdminController.java of PublicCMS v4.0.202406 allows attackers to execute arbitrary code via uploading a crafted svg or xml file.Enginsight
| Vendor | Product | Version |
|---|---|---|
| publiccms | publiccms | 4.0.202406.f:f |
𝑥
= Vulnerable software versions
Common Weakness Enumeration